Don’t let overlooked obligations become incidents. Learn how.
Utility navigation bar redirect icon
Portal LoginSupportBlogContact
Search
Close search
Huntress Logo in Teal
  • Platform Overview
    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed ITDR: Identity Threat Detection and Response

    Protect your Microsoft 365 and Google Workspace identities and email environments.

    Managed ITDR: Identity Threat Detection and Response

    Protect your Microsoft 365 and Google Workspace identities and email environments.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed Security Awareness Training Software

    Empower your teams with science-backed security awareness training.

    Managed Security Awareness Training Software

    Empower your teams with science-backed security awareness training.

    Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Managed ESPM

    Proactively secure endpoints against attacks.

    Managed ESPM

    Proactively secure endpoints against attacks.

    Integrations
    Integrations
    Support Documentation
    Support Documentation
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
  • Threats We Stop
    Phishing
    Phishing
    Business Email Compromise
    Business Email Compromise
    Ransomware
    Ransomware
    Infostealers
    Infostealers
    View Allright arrowView Allright arrow
    Industries We Serve
    Education
    Education
    Financial Services
    Financial Services
    State and Local Government
    State and Local Government
    Healthcare
    Healthcare
    Law Firms
    Law Firms
    Manufacturing
    Manufacturing
    Utilities
    Utilities
    View Allright arrowView Allright arrow
    Tailored Solutions
    MSPs
    MSPs
    Resellers
    Resellers
    SMBs
    SMBs
    Compliance
    Compliance
    What Gets Overlooked Gets Exploited

    Most days, nothing happens. But one day, something will.

    Huntress Cybersecurity
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
  • Pricing
  • Community Series
    The Product Lab

    Shape the next big thing in cybersecurity together.

    The Product Lab

    Shape the next big thing in cybersecurity together.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    Resources
    Upcoming Events
    Upcoming Events
    Ebooks
    Ebooks
    On-Demand Webinars
    On-Demand Webinars
    Videos
    Videos
    Whitepapers
    Whitepapers
    Datasheets
    Datasheets
    Cybersecurity Education
    Cybersecurity 101
    Cybersecurity 101
    Cybersecurity Guides
    Cybersecurity Guides
    Threat Library
    Threat Library
    Real Tradecraft, Real Results
    Real Tradecraft, Real Results
    2026 Cyber Threat Report
    2026 Cyber Threat Report
    The Huntress Blog
    Exposed RDP: The Misconfiguration that Keeps Paying Off
    Huntress Cybersecurity
    Exposed RDP: The Misconfiguration that Keeps Paying Off
    Huntress Cybersecurity
    Defending EDR Against Adversaries
    Huntress Cybersecurity
    Defending EDR Against Adversaries
    Huntress Cybersecurity
    19 Cloud Security Challenges and How to Mitigate Risk
    Huntress Cybersecurity
    19 Cloud Security Challenges and How to Mitigate Risk
    Huntress Cybersecurity
  • Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    The Huntress SOC

    24/7 Security Operations Center

    The Huntress SOC

    24/7 Security Operations Center

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Community

    Get in touch with the Huntress Community team

    Community

    Get in touch with the Huntress Community team

    Compare Huntress
    Bitdefender
    Bitdefender
    Blackpoint
    Blackpoint
    Breach Secure Now!
    Breach Secure Now!
    Crowdstrike
    Crowdstrike
    Datto
    Datto
    SentinelOne
    SentinelOne
    Sophos
    Sophos
    Compare Allright arrowCompare Allright arrow
  • HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    Partners
    MSPs

    Join our partner community to deliver expert-led managed security.

    MSPs

    Join our partner community to deliver expert-led managed security.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Tech Alliances

    Driving innovation through global technology Partnerships

    Tech Alliances

    Driving innovation through global technology Partnerships

    Microsoft Partnership

    A Level-Up for Your Business Security

    Microsoft Partnership

    A Level-Up for Your Business Security

  • Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Awards
    Awards
    Contact Us
    Contact Us
  • Portal Login
  • Support
  • Blog
  • Contact
  • Search
  • Get a Demo
  • Start for Free
Portal LoginSupportBlogContact
Search
Close search
Get a Demo
Start for Free
HomeBlog
Exposed RDP: The Misconfiguration that Keeps Paying Off
Published:
May 19, 2026

Exposed RDP: The Misconfiguration that Keeps Paying Off

By:
Beth Robinson
Share icon
Glitch effectGlitch effectGlitch effect

Key Takeaways

  • Exposed RDP is still one of the most overlooked vulnerable exposures. Security teams are stretched thin, alerts are buried in noise, and known misconfigurations quietly slip through the cracks before anyone gets to them.
  • Attackers are automated and opportunistic. They scan the entire internet looking for open ports like 3389, meaning any exposed RDP is essentially a standing invitation regardless of your organization's size or profile.
  • An unresolved exposure will be exploited again. When an attacker returns to the same entry point the next day with a different compromised account, that's not bad luck. It's a predictable consequence of not closing the gap after the first incident.
  • Resilience beats perfection. Misconfigurations will happen, but organizations that layer Managed Security Event and Information Management (SIEM) with Managed Endpoint Detection and Response (EDR) can catch oversights before they become catastrophes.


There's a skeleton lurking in business environments everywhere. It's been there for years. It's not glamorous, and it doesn't make headlines like zero days. But it keeps showing up in our Security Operations Center (SOC) cases again and again.

It's Remote Desktop Protocol (RDP) that’s exposed to the internet. And it is still one of the most reliable ways for attackers to access your environment in 2026.

These are real-world stories of overlooked RDP exposures that didn't turn into full-blown security incidents because the organizations involved had already invested in resilient security programs.


Why RDP gets overlooked

The teams responsible for catching these exposures are often stretched thin.

According to a recent Huntress survey of 1,050 IT and security professionals, the most common security team sizes fall between 6–10 people (21.4%) and 11–15 people (19%). More telling: only 39.6% of organizations have a dedicated in-house cybersecurity team. Another 35% share IT and security responsibilities, and 18% rely on a single person.

That's a lot of responsibility concentrated in very few hands. And when those hands are busy, things fall through the cracks, like an exposed RDP port that got flagged six months ago but moved to the bottom of the backlog.

Alert noise makes it worse. Nearly two-thirds of respondents (64.1%) report that at least 25% of their alerts are meaningless noise. When every alert looks the same, the real ones get buried.

As Chris Henderson, Chief Information Security Officer at Huntress, puts it: 

"People don't fail because they're careless. They fail because they're human, and the systems weren't designed to catch these human mistakes."

Resilient teams know they won't catch everything. They build their programs to surface oversights before attackers can do lasting damage.


Overlooked risks are cybercrime business opportunities

The gaps in the stories below aren't sophisticated. And they’re not zero day vulnerabilities. They’re just configurations probably flagged at some point, added to a backlog, and quietly forgotten.

What’s worse is that threat actors have built an entire business model around your backlog. Just like you, they’re running a profit-driven business, with communication networks, finances, and support services. They're methodical. They're organized. And just like any other legit competitor, this hidden competition will find the vulnerable thing you forgot about, like exposed RDP, and use it against you over and over again. To understand why your oversight is their opportunity, you can start here:


They’re not targeting you. They’re testing everyone.  

Threat actors aren't always specifically hunting your business. In many cases, they're running automated scans across the internet, testing every possible weakness until something gives.

That's exactly what happened at a healthcare organization that had left an RDP server exposed to the public internet. The attacker didn't need sophisticated tradecraft or an exploit. They simply found the open port (typically 3389) and the intrusion began.

Security Information and Event Management (SIEM) detected the breach at the moment of initial access, and the SOC kicked out the attacker before they gained persistence.

The whole situation was entirely preventable by putting RDP behind a firewall. That one configuration change is the difference between an eyebrow-raising non-event and a business-stopping incident.

Figure 1: Huntress incident report exposing a compromised RDP server


They'll come back. Especially if nothing changes.

In another case, a threat actor accessed a client environment through an exposed Remote Desktop Web Access (RDWeb) portal. RDWeb is a Microsoft component that uses RDP technology for users to securely access internal company applications or full desktops via a web browser. In this incident, the attackers brought a custom-built reverse tunnel for persistent access, with Windows and Linux builds, and automated credential-harvesting scripts running in the background.

Our SOC quickly contained the threat, shut down the attackers, and reported back to the partner.

But the next morning, the attackers returned to the same exposed RDWeb portal. It was a different compromised account, but the same entry point. They didn't need to try anything new, because nothing had changed.

The same vulnerable exposure was exploited twice because it wasn’t closed fast enough. That's the reality of overlooked risks. 

Figure 2: Exposed RDWeb attack path


They just need your tools

Exposed RDP is more than just an entry point. Once an attacker is inside, they'll use it to dig in deeper in your environment.

Our SOC caught a cybercriminal who compromised a partner's network through a vulnerable SonicWall VPN, using cheap $10 hosting infrastructure (Hostinger and Freakhosting) as a launchpad. Once inside, the attacker moved laterally and modified the firewall and registry values to enable RDP. Here are the commands this attacker used:

reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f

net stop TermService && timeout /t 2 && net start TermService

reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f

netsh advfirewall firewall add rule name="RDP-Open" dir=in protocol=TCP localport=3389 action=allow enable=yes

netsh advfirewall firewall add rule name="RDP-Open" dir=in protocol=TCP localport=3389 action=allow enable=yes

netsh advfirewall firewall set rule group="Remote Desktop" new enable=yes

This was followed by authentication from a known malicious workstation and Advanced IP scanner for more enumeration. 

This organization had the right defenses in place. Managed Endpoint Detection and Response (EDR) caught the lateral movement before the attacker could establish a foothold.

Figure 3: Tracking the attacker's steps to enable RDP access


What these cases are actually telling you to do

These were opportunistic attacks. And each case points to a specific gap worth closing.

The healthcare organization with the open RDP port needed a simple configuration change: RDP behind a firewall. If you don't know whether RDP is exposed on your network, look into it today. Tools like Shodan or a basic external scan of your IP space will help. That's your starting point.

The organization that got hit twice had a different problem. The entry point was a known vulnerable exposure, and it stayed open. When an attacker accesses your environment through a specific exposure, close it and rotate the credentials associated with it before they come back. Because, as that case shows, they will.

The SonicWall case is a reminder that attackers will use your own legitimate and trusted tools. EDR is essential, but if you're not ingesting firewall and VPN logs into a SIEM, you don’t have an early warning system, and an attacker can persist in your environment for days before you see the first shady signal. Visibility across your full attack surface, not just endpoints, is what catches the things that slip through the cracks.

The bottom line across all three: these organizations were caught off guard by a common oversight, not surprised by a zero day. 


Invest in resilience

Misconfigurations happen. Exposed ports get missed. Backlogs grow. The cybercrime business model moves faster than any security checklist.

Resilience isn't about preventing every mistake. It's about limiting impact and recovering quickly when oversights happen. As Eric Stride, Chief Security Officer at Huntress, says in the Huntress How to Build a Resilient Security Team for 2030 field guide: 

"The goal isn't to eliminate every risk. It's to build a system your team trusts when something goes wrong."

In every incident described here, the organizations survived because they had the right layers in place to catch exposures before they became a catastrophe.

Fix the misconfigurations you know about. And make sure someone's watching for the ones you don't.









Categories
Cybersecurity Education
ChatGPT logoChatGPTOpens in new tabClaude logoClaudeOpens in new tabPerplexity logoPerplexityOpens in new tabGoogle Gemini logoGoogle AIOpens in new tab
AI sparkle iconSummarize This Page
ChatGPT logoChatGPTOpens in new tabClaude logoClaudeOpens in new tabPerplexity logoPerplexityOpens in new tabGoogle Gemini logoGoogle AIOpens in new tab

What's your social profile giving away?

On May 20 (12pm EST), join Truman Kain and Caitlin Sarian ("Cybersecurity Girl") for the latest edition of _declassified and learn how attackers turn social media into intel.
Grab your spot
Share
Facebook iconTwitter X iconLinkedin iconDownload icon
Glitch effect

You Might Also Like

  • Malware Deep Dive: Examining A PowerShell Payload

    To avoid detection, hackers often turn a system’s own tools against itself. Here, we examine a malicious payload that was executed using PowerShell.
  • Your Security Program Was Built for a Threat Landscape That No Longer Exists

    Security programs are failing against modern identity threats. See new Huntress data to discover a roadmap to building a resilient security team.
  • The Ultimate Validation: Making a Hacker’s “Do Not Engage” List

    When Celestial Stealer runs in the wild, it looks for Huntress’ own Jai Minton as a potential threat, and this shuts down the infostealer operation if his name is detected.
  • Take Control: Locking Down Common Endpoint Vulnerabilities

    Learn how to lock down common endpoint vulnerabilities like weak passwords and unpatched software to secure your systems against threats like phishing and malware.
  • Securing Your Business: The Vital Role of Cyber Insurance

    Understand the critical role of cyber insurance in safeguarding your business from cyber threats. Learn how this coverage can protect your assets.
  • You’re the “Why” Behind the Huntress Hub

    Huntress Hub is here. It’s your all-in-one portal for resources, training, and marketing tools to empower your cybersecurity journey. Simplify workflows, boost productivity, and grow your business with ease.
  • How a Proactive Account Review Uncovered Unauthorized Surveillance Tools

    A routine account review revealed the use of productivity monitoring tools in a medical clinic, highlighting the hidden risks associated with employee monitoring software. Learn the importance of proactive audits in protecting critical systems and sensitive data from potential threats.
  • Make Your Microsoft Security Tools Come to Life with Huntress

    Huntress joins the Microsoft Intelligent Security Association to enhance Microsoft tools for SMBs, delivering stronger defenses against today’s most advanced cyber threats.

Sign Up for Huntress Updates

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.
Privacy • Terms
By submitting this form, you accept our Terms of Service & Privacy Policy
Huntress Managed Security PlatformManaged EDRManaged EDR for macOSManaged EDR for LinuxManaged ITDRManaged SIEMManaged Security Awareness TrainingManaged ISPMManaged ESPMBook a Demo
PhishingComplianceBusiness Email CompromiseEducationFinanceHealthcareManufacturingState & Local Government
Managed Service ProvidersResellersIT & Security Teams24/7 SOCCase Studies
BlogResource CenterCybersecurity 101Upcoming EventsSupport Documentation
Our CompanyLeadershipNews & PressCareersContact Us
Huntress white logo

Protecting 250k+ customers like you with enterprise-grade protection.

Privacy PolicyCookie PolicyTerms of UseCookie Consent
Linkedin iconTwitter X iconYouTube iconInstagram icon
© 2025 Huntress All Rights Reserved.

Join the Hunt

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy